vulnerability-deduplication
Installation
SKILL.md
Vulnerability Deduplication
Overview
This skill enables vulnerability management teams to identify and consolidate duplicate vulnerability records that arise when multiple scanners report the same CVE against the same asset. Deduplication reduces noise, improves remediation efficiency, and provides an accurate count of the organization's true vulnerability exposure.
Key capabilities:
- Identify duplicate vulnerable items by matching CVE ID and configuration item
- Detect near-duplicates from different scanner sources reporting the same issue
- Consolidate redundant remediation tasks into a single actionable item
- Prioritize deduplicated vulnerabilities using CVSS scores and business criticality
- Generate reports showing duplicate reduction and true exposure counts
- Maintain audit trail of deduplication decisions
When to use: After vulnerability scan imports, during periodic vulnerability hygiene reviews, when onboarding a new scanner, or when vulnerability counts seem inflated due to multi-scanner overlap.